PT-2010-4052 · Php · Php

Tomas Hoger

·

Publicado

2010-08-20

·

Atualizado

2016-08-23

·

CVE-2010-2484

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP versions prior to 5.2.14
Description The issue allows context-dependent attackers to obtain sensitive information, such as memory contents, or trigger memory corruption. This can be achieved by causing a userspace interruption of an internal function or handler, specifically through the strrchr function.
Recommendations For PHP versions prior to 5.2.14, update to version 5.2.14 or later to resolve the issue. As a temporary workaround, consider restricting the use of the strrchr function until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2484

Produtos afetados

Php